Authenticating and authorizing user equipment
By preloading authentication and authorization data at the radio network node, the method addresses the energy and latency challenges of ZE-IoT devices, facilitating efficient network access without core network interaction.
Patent Information
- Application Number
- PCT/CN2024/085430
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-02
- Publication Date
- 2025-10-09
AI Technical Summary
ZE-IoT devices face challenges in completing authentication and authorization procedures due to limited energy and network coverage, leading to excessive power consumption and latency.
A radio network node preloads authentication and authorization data from the core network, allowing the UE to perform these procedures efficiently without interacting with the core network, reducing energy use and latency.
This approach enables quicker and more energy-efficient authentication and authorization for ZE-IoT devices, optimizing their energy use for data transmission and reception.
Smart Images

Figure CN2024085430_09102025_PF_FP_ABST
Abstract
Description
AUTHENTICATING AND AUTHORIZING USER EQUIPMENTTECHNICAL FIELD
[0001] The present disclosure relates generally to wireless communication technologies and, more particularly, to methods and systems for authenticating and authorizing user equipment (UE) in a cellular network.BACKGROUND
[0002] Wireless Internet of Things (IoT) devices are increasingly prevalent in various applications, including asset tracking and environmental or industrial sensing. Traditional wireless IoT devices, often battery-powered, present challenges related to battery life and the need for battery replacement. Consequently, there is an industry shift toward Zero-Energy (ZE) devices, which are characterized by their ability to harvest energy from environmental sources or by utilizing back-scattering communication techniques, negating the need for manual battery replacement or recharging.
[0003] ZE-IoT devices are designed for ultra-low power consumption and may employ small disposable batteries or have a limited capacity. These devices can be highly compact, and are aimed at autonomous energy operation for their lifetime. The operational paradigm for ZE-IoT devices introduces novel requirements for the radio interface and associated protocols.
[0004] Recent advancements have been initiated by the 3rd Generation Partnership Project (3GPP) , coining the term 'Ambient-IoT' (A-IoT) . Technical Report (TR) 22.840 by Study Group 1 (SA1) identifies prospective use cases, device constraints, and introduces new service requirements and Key Performance Indicators (KPIs) for A-IoT.
[0005] Limited by hardware capabilities (e.g. memory, RF, or power) , an A-IoT UE may have very limited power and / or network coverage. It is thus a challenge for the UE to follow the legacy procedures for a complete authentication and authorization procedure, since the legacy procedure requires a nonnegligible latency involving multiple signalling messages exchanged between the UE and the Access and Mobility Management Function (AMF) , between the AMF and other core network (CN) entities including Session Management Function (SMF) , Authentication Server Function (AUSF) , Policy Control Function (PCF) etc. The energy stored in the UE (e.g. collected via energy harvesting) may be insufficient for the UE to finish the authentication and authorization procedure and subsequent data transfer / reception.SUMMARY
[0006] One object is to make the authentication an authorization of a UE more efficient for the UE.
[0007] According to a first aspect, it is provided a method for authenticating and authorizing a user equipment, UE, the method being performed by a radio network node of a cellular network. The method comprises: receiving data for authentication and authorization of the UE from a core network; and performing an authentication and authorization check with the UE based on the data for authentication and authorization.
[0008] The method may further comprise, prior to the receiving data for authentication and authorization: determining that data for authentication and authorization of the UE is to be obtained; and transmitting a request for data for authentication and authorization of the UE to the core network, wherein the request comprises an identifier of the UE.
[0009] The request for data for authentication and authorization of the UE may comprise an energy category of the UE, wherein the energy category indicates an energy capability of the UE.
[0010] The request for data for authentication and authorization of the UE may comprise a connection category of the UE, wherein the connection category is one of: the UE being directly connected to the radio network node, the UE being indirectly connected to the radio network node, and the UE not being connected to the radio network node.
[0011] The determining that data for authentication and authorization of the UE is to be obtained may comprise determining that the UE is located within a coverage area of the radio network node.
[0012] The determining that data for authentication and authorization of the UE is to be obtained may comprise determining that there is downlink data for the UE.
[0013] The determining that data for authentication and authorization of the UE is to be obtained may comprise communicating with the UE.
[0014] The method may further comprise: transmitting a result of the authentication and authorization to the core network
[0015] The data for authentication and authorization may comprise data for authentication comprising at least one of: an identifier of the UE, a digital key associated with the UE, a digital token associated with the UE and a digital signature applied by the core network.
[0016] The data for authentication and authorization may comprise data for authorization comprising at least one of: an indication that the UE is authorized to operate as a UE on the cellular network, an indication whether the UE allows authentication and authorization by the radio network node, and an indication what services, traffic types or applications that the UE is allowed to access.
[0017] The method may further comprise: providing the data for authentication and authorization for the UE to a target radio network node of an expected change of radio network node of the UE.
[0018] According to a second aspect, it is provided a radio network node for authenticating and authorizing a user equipment, UE, the radio network node being configured to form part of a cellular network. The radio network node comprises: processing circuitry; and memory circuitry storing instructions that, when executed by the processing circuitry, cause the radio network node to: receive data for authentication and authorization of the UE from a core network; and perform an authentication and authorization check with the UE based on the data for authentication and authorization.
[0019] The radio network may further comprise instructions that, when executed by the processing circuitry prior to the instructions to receive data for authentication and authorization, cause the radio network node to: determine that data for authentication and authorization of the UE is to be obtained; and transmit a request for data for authentication and authorization of the UE to the core network, wherein the request comprises an identifier of the UE.
[0020] The request for data for authentication and authorization of the UE may comprise an energy category of the UE, wherein the energy category indicates an energy capability of the UE.
[0021] The request for data for authentication and authorization of the UE may comprise a connection category of the UE, wherein the connection category is one of: the UE being directly connected to the radio network node, the UE being indirectly connected to the radio network node, and the UE not being connected to the radio network node.
[0022] The instructions to determine that data for authentication and authorization of the UE is to be obtained may comprise instructions that, when executed by the processing circuitry, cause the radio network node to determine that the UE is located within a coverage area of the radio network node.
[0023] The instructions to determine that data for authentication and authorization of the UE is to be obtained may comprise instructions that, when executed by the processing circuitry, cause the radio network node to determine that there is downlink data for the UE.
[0024] The instructions to determine that data for authentication and authorization of the UE is to be obtained may comprise instructions that, when executed by the processing circuitry, cause the radio network node to communicate with the UE.
[0025] The radio network node may further comprise instructions that, when executed by the processing circuitry, cause the radio network node to: transmit a result of the authentication and authorization to the core network
[0026] The data for authentication and authorization may comprise data for authentication comprising at least one of: an identifier of the UE, a digital key associated with the UE, a digital token associated with the UE and a digital signature applied by the core network.
[0027] The data for authentication and authorization may comprise data for authorization comprising at least one of: an indication that the UE is authorized to operate as a UE on the cellular network, an indication whether the UE allows authentication and authorization by the radio network node, and an indication what services, traffic types or applications that the UE is allowed to access.
[0028] The radio network node may further comprise instructions that, when executed by the processing circuitry, cause the radio network node to: provide the data for authentication and authorization for the UE to a target radio network node of an expected change of radio network node of the UE.
[0029] According to a third aspect, it is provided a computer program for authenticating and authorizing a user equipment. The computer program comprises computer program code which, when executed on a radio network node forming part of a cellular network causes the radio network node to: receive data for authentication and authorization of the UE from a core network; and perform an authentication and authorization check with the UE based on the data for authentication and authorization.
[0030] According to a fourth aspect, it is provided a computer program product comprising a computer program according to the third aspect and a computer readable means comprising non-transitory memory in which the computer program is stored.
[0031] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, step, etc. " are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Aspects and embodiments are now described, by way of example, with refer-ence to the accompanying drawings, in which:
[0033] Figs 1A-B are schematic diagrams illustrating environments in which embodiments presented herein can be applied;
[0034] Figs 2A-B are swimlane diagrams illustrating embodiments of methods for authenticating and authorizing a UE;
[0035] Fig 3 is a schematic diagram illustrating components of the radio network node of Figs 1A-B;
[0036] Fig 4 is a schematic diagram showing functional modules of the radio network nodes of Figs 1A-B according to one embodiment; and
[0037] Fig 5 shows one example of a computer program product comprising computer readable means.DETAILED DESCRIPTION
[0038] The aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown. These aspects may, however, be embodied in many different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and to fully convey the scope of all aspects of invention to those skilled in the art. Like numbers refer to like elements throughout the description.
[0039] According to embodiments presented herein, instead of the UE interacting with the core network for authentication and authorization, the radio network node preloads data for authentication and authorization from the core network, and the radio network node performs the procedure for authentication and authorization with the UE based on the data from the core network. This allows the UE to perform the procedure for authentication and authorization quicker and easier than what is done in legacy procedures. In this way, energy use and latency for the UE is reduced, making proper authentication and authorization possible for devices for which the legacy procedures for authentication and authorization consume an excessive amount of power and time.
[0040] Figs 1A-B are schematic diagrams illustrating environments in which embodiments presented herein can be applied. Looking first to Fig 1A, it is shown a cellular network 9 where embodiments presented herein may be applied. The cellular network 9 comprises a core network 3 and one or more base stations 1, here in the form of gNode Bs, also known as gNBs. The base station 1 could also be in the form of eNode Bs, Node Bs, etc. or any other suitable base station. The base station 1 forms part of a radio access network (RAN) for radio connectivity over a wireless interface 4 to a plurality of UEs 2. However, while applicable for multiple UEs, for ease of comprehension and clarity, the relationship with one base station 1 and one UE 2 is described hereinafter. The term UE 2 is also known as mobile communication terminal, wireless device, mobile terminal, user terminal, user agent, wireless terminal, machine-to-machine device, etc., and can be implemented, for example, in what today is commonly known as an Ambient-IoT device, an IoT device, a mobile phone, smartphone or a tablet / laptop with wireless connectivity.
[0041] The UE 2 can optionally be classified according to its capability in terms of energy storage, and generating RF signals for its transmissions. For instance, the UE 2 can be provided with no energy storage at all, or with (often limited) energy storage.
[0042] As an example, the following classification can be done of UEs 2.
[0043] Type A: No energy storage, no independent signal generation / amplification, i.e. backscatter transmission.
[0044] Type B: Has energy storage, no independent signal generation, i.e. backscattering transmission. The stored energy can be used to amplify reflected signals.
[0045] Type C: Has energy storage, has independent signal generation, i.e. active RF components for transmission.
[0046] The amount of energy storage can be different among UEs 2 within type B or UEs 2 within type C, and different between type B and type C.
[0047] UEs 2 of type A, B, and C are able to demodulate control, data, etc from the relevant entity in a RAN according to connectivity topology.
[0048] The cellular network 9 can e.g. comply with any one or a combination of 5G NR (New Radio) , 6G, LTE (Long Term Evolution) , LTE Advanced, W-CDMA (Wideband Code Division Multiplex) , or any other current or future wireless network, as long as the principles described hereinafter are applicable.
[0049] Over the wireless interface 4, downlink (DL) communication occurs from the base station 1 to the UE 2 and uplink (UL) communication occurs from the UE 2 to the base station 1. The quality of the wireless radio interface to each UE 2 can vary over time and depending on the position of the UE 2, due to effects such as fading, multipath propagation, interference, etc.
[0050] The base station 1 is also connected to the core network 3 for connectivity to central functions and a wide area network 7, such as the Internet.
[0051] Looking now to Fig 1B, an intermediate node 5 is provided between the base station 1 and the UE 2. The intermediate node can e.g. be a relay, Integrated Access and Backhaul (IAB) node, another UE, repeater, etc. The intermediate node 5 transfers data and / or signalling between the base station 1 and the UE 2.
[0052] Optionally, the UE 2 communicates directly with the base station 1 for downlink communication but communicates via the intermediate node 5 for uplink communication, or vice versa.
[0053] Authentication and authorization are two processes for security purposes. The authentication verifies the identity, e.g. of a UE 2 or service, and the authorization determines their access rights to the network and / or the service.
[0054] Whenever the term radio network node is used herein, this applies to either one of the base station 1 or the intermediate node 5.
[0055] According to embodiments presented herein, the radio network node 1, 5 preloads data for authentication and authorization, to allow an efficient procedure for authentication and authorization to be performed with the UE 2. In this way, the UE 2 is relieved from the task of communicating with the core network 3 for authentication and authorization.
[0056] Figs 2A-B are swimlane diagrams illustrating embodiments of methods for authenticating and authorizing a UE 2. The swimlane diagrams can be considered to comprise a flow chart for methods performed by the UE 2 on the left, a flow chart for methods performed by the radio network node 1, 5 in the middle, and a flow chart for methods performed by the core network 3 on the right. Communication between the entities is also shown.
[0057] In a transmit AA (authentication and authorization) data step 144, the core network 3 transmits authentication and authorization data 22 to the radio network node 1, 5. In one embodiment, the core network 3 transmits the data for authentication and authorization without being requested to do so, i.e. in a push data flow. This can e.g. be based on the core network 3 having learned that a UE 2 may soon be served by the radio network node. Based on this, the core network 3 determines to send the authentication and authorization information to the radio network node to preload the data to the radio network node.
[0058] Optionally, the data for authentication and authorization comprises a validity time indicating for how long the radio network node is allowed to apply the data of authentication and authorization.
[0059] Alternatively or additionally, the radio network node is only allowed to fetch data for authentication and authorization for a particular geographic location.
[0060] In a receive AA data step 44, the radio network node 1, 5 receives the data 22 for authentication and authorization of the UE 2 from the core network 3, such as from any one or more of the AMF, SMF, AUSF and PCF of the core network 3.
[0061] The data 22 for authentication and authorization can comprise data for authentication. Such data for authentication can comprise at least one of: an identifier of the UE 2, a digital key associated with the UE 2, a digital token associated with the UE 2 and a digital signature applied by the core network 3. Such data for authentication can concern one UE 2 or several UEs 2.
[0062] Additionally, the data 22 for authentication and authorization can comprise data for authorization. Such data for authorization can comprise at least one of: an indication that the UE 2 is authorized to operate as a UE 2 on the cellular network 9, an indication whether the UE 2 permits authentication and authorization by the radio network node 1, 5, and an indication of what services, traffic types or applications that the UE 2 is allowed to access (e.g. according to the classification in Type A, B or C mentioned above) . The data for authorization can also optionally include: Information indicating whether the UE 2 accepts authentication and authorization by one particular radio network node, or by any radio network node, or only by the CN. The data for authorization can also optionally include information indicating whether the UE 2 is authorized to access, via the radio network node, one or multiple PLMNs (Public Land Mobile Network) , or any network ID, e.g. non-public / private network.
[0063] The data for authorization can also optionally include information indicating whether the UE 2 is authorized to access a second radio network node via a first radio network node.
[0064] The data for authorization can also optionally include information indicating whether the UE 2 is authorized to access one or multiple services, traffic types or applications via the radio network node.
[0065] Such data for authorization can concern one UE 2 or several UEs 2.
[0066] In a perform AA with UE step 46, the radio network node 1, 5 performs an authentication and authorization check with the UE 2 based on the data 22 for authentication and authorization.
[0067] On the UE side, the UE 2 collaborates with the radio network node 1, 5 for authentication and authorization in a support AA step 46. Optionally, the UE 2 authenticates and authorizes the radio network node in this step, e.g. by checking validity of signals from the radio network node.
[0068] The authentication and authorization of the UE 2 can be triggered by the UE 2 initiating an uplink transmission towards the radio network node 1, 5. Since the data for the authentication and authorization has been preloaded to the radio network node 1, 5, the authentication and authorization for the UE 2 is completed within the RAN, without involving the core network 3 during the procedure. Consequently, the latency of the authentication and authorization procedure is reduced, so that the UE 2 can better utilize its energy for data transmission or data reception.
[0069] Optionally, the data for authentication and authorization becomes invalid for the radio network node when one or more of the invalidation conditions mentioned here below are met.
[0070] One invalidation condition is that a validity timer expires. The validity timer is started when the radio network node receives the data for the UE 2. The timer expires after a certain time period in the radio network node for the UE 2 that can be configured based on or more parameters, e.g. based on the UE’s category, the UE’s employed services / traffic types / applications, the UE’s subscription etc. Different UEs 2 may be associated with different timer durations.
[0071] One invalidation condition is that the radio network node leaves a geographic area for which validity is defined. One invalidation condition is that the UE 2 has left the radio network node coverage area. One invalidation condition is that a request of authentication and authorization is received from the core network 3. One invalidation condition is that an indication is received from the core network 3, indicating that authentication and authorization for the UE 2 has changed. One invalidation condition is that a command is received from the core network 3 to disable authentication and authorization by the radio network node. One invalidation condition is that a UE 2rejects authentication and authorization requests from the radio network node.
[0072] One invalidation condition is that the UE 2 has no energy (cannot collect energy via energy harvesting) over a certain time period, which is configured in the radio network node for the UE 2. The radio network node may learn this information via the UE’s energy info report. In an example, an energy report from the UE 2 has indicated that the current energy in the UE 2 has already been exhausted, optionally a certain time period ago. In an example, the radio network node has not received any uplink signal or any energy report from the UE 2 over a certain time period.
[0073] Optionally, the radio network node determines to update or discard authentication and authorization data for the UE when one or more of the invalidation conditions are true. When an update is determined, the radio network node attempts to fetch new data from the core network 3 for the UE 2. When discarding is determined, the radio network node discards the data without further action. The radio network node may perform actions (either to fetch new data or discard) for the UE 2 based on a signalling received from the core network 3, or a signalling received from the UE 2 itself, as described elsewhere herein.
[0074] As explained above, the active steps of the radio network node for authentication and authorization can be implemented in a base station 1 or in an intermediate node 5.
[0075] When the radio network node is implemented in the base station 1, and there is an intermediate node present, the intermediate node 5 simply relays data to and from the UE 2 transparently. The intermediate node 5 is not required to decode or read the data.
[0076] When the radio network node is implemented in the intermediate node 5, it is the intermediate node that receives and store authentication and authorization data for the UE 2. The data can be fetched by the intermediate node 5 from the base station 1. The intermediate node 5 can fetch the data from the base station 1 beforehand or upon reception of the uplink transmission from the UE 2. When fetched beforehand, the intermedia node 5 predicts or determines presence of the UE 2 to be in the proximity of the intermediate node 5. In one embodiment, the intermediate node 5 monitors transmissions from the UE 2. If the intermediate node 5 receives signalling or a transmission from the UE 2, this indicates that the UE 2 in proximity to the intermediate node 5. The intermediate node 5 can then fetch the data of authentication and authorization from the base station 1 for the UE 2 in advance (i.e. before receiving a connection request from the UE 2) . Alternatively, the intermediate node fetches the data of authentication and authorization for the UE 2 from the core network 3 (e.g. AMF) . The intermediate node 5 may further inform the base station 1 and / or the core network 3 of the outcome of the authentication and authorization procedure for the UE 2. When the base station 1 receives the outcome of the authentication and authorization procedure for the UE 2, the base station 1 may further inform the core network 3.
[0077] In one embodiment, when the intermediate node 5 hands over the UE 2 to another radio network node, the intermediate node informs the UE 2 of the new radio network node, and may send the stored data of authentication and authorization for the UE 2 to the target radio network node. In this way, the target radio network node does not need to fetch the data for authentication and authorization for the UE 2 from the core network 3.
[0078] Looking now to Fig 2B, only steps that are added or different to those presented above will be described.
[0079] In an optional determine AA data need step 40, the radio network node 1, 5 determines that data for authentication and authorization of the UE 2 is to be obtained. This implements a pull-based data flow. The need for AA data can be based on determining that the UE 2 is located within a coverage area of the radio network node 1, 5. Alternatively or additionally, the need for AA data can be based on determining that there is downlink data for the UE 2. Alternatively or additionally, the need for AA data can be based on communicating with the UE 2.
[0080] Alternatively or additionally, the need for AA data can be based on the UE 2 being static and located within the radio network node coverage area. In one example, the UE 2 could have been deployed in the coverage area of the radio network node at an earlier stage, in which case the UE’s information has been logged and stored in the radio network node. In one example, the UE 2 is newly deployed in the coverage area of the radio network node, in which case the UE’s information can be obtained from the operations and management system.
[0081] Alternatively or additionally, the need for AA data can be based on the UE 2 moving into the coverage area of the radio network node.
[0082] In one embodiment, the UE 2 sends a signal to the radio network node indicating that the UE 2 intends to access the radio network node. In one example, the signals may be a periodic UL signal transmitted by the UE 2 automatically. In one example, the UE 2 determines that its position has changed with respect to 3GPP compatible or non-3GPP compatible technology, and the UE 2 moves towards the radio network node. The UE 2 may then transmit a UL signal to the radio network node. In one example, the signal may be a response massage responding to paging / polling from the radio network node, e.g. the response message by the UE 2 when responding the first time responds to the paging / polling / other signals from the radio network node. For instance, the response massage can initiate the first time reception by the UE 2 responding to the paging / polling / other signals from the radio network node, and / or the response massage carries an ID of the UE 2, whereby the radio network node may know it is a new UE 2 from outside of the coverage area of the radio network node.
[0083] Based on positioning or sensing signals, the radio network node can detect that the UE 2 is moving towards the radio network node, and will soon be within the radio network node coverage area.
[0084] In one example, the radio network node may command the UE 2 to transmit a UL positioning signal (a single time or repetitively) e.g. an UL Sounding Reference Signal (SRS) . In one example, the radio network node may transmit a sensing signal to the UE 2, with reflection / backscattering, the UE 2 may reflect the sensing signal back to the radio network node. This is especially useful when the UE 2 moves within a limited area, i.e. the radio network node knows the UE 2 from before being within the area served by multiple radio network nodes, which radio network node actually serves the UE 2 could be determined based on sensing as described above.
[0085] Alternatively or additionally, the need for AA data can be based on there being DL data towards the UE 2. In this case, the radio network node may have no direct knowledge on the UE’s location at the time.
[0086] Alternatively or additionally, the need for AA data can be based on a CN entity indicating that the radio network node is enabled to fetch authentication and authorization data.
[0087] Alternatively or additionally, the need for AA data can be based on the UE 2 triggering the authentication and authorization procedure, but the radio network node does not yet have any available authentication and authorization data for the UE 2. The radio network node may inform the UE 2 to perform authentication and authorization after a certain time period, during which the radio network node fetches authentication and authorization data for the UE 2. The UE 2 could go into energy saving mode during this time period, thus saving UE 2 energy.
[0088] Alternatively or additionally, the need for AA data can be based on the UE 2 having limited energy, which is not sufficient for the UE 2 to perform the authentication and authorization procedure with the core network entities (e.g. AMF, SMF, AUSF or PCF) by exchanging the signalling messages (e.g. Non-Access Stratum (NAS) signalling) . In one example, the UE 2 may send the energy report to any nearby radio network node in broadcast. the energy report may be a L1 (level 1) signalling or L2 (level 2) signalling.
[0089] In an optional request AA data step 42, the radio network node 1, 5 transmits a request 20 for data for authentication and authorization of the UE 2 to the core network 3. Such a request 20 comprises an identifier of the UE 2. Optionally, the request 20 comprises identifiers of multiple UEs.
[0090] The request 20 for data for authentication and authorization of the UE 2 can comprise an energy category of the UE 2, wherein the energy category indicates an energy capability of the UE 2.
[0091] The request 20 for data for authentication and authorization of the UE 2 can comprise a connection category (e.g. one of Types A, B, and C mentioned above) of the UE 2. The connection category is then one of: the UE 2 being directly connected to the radio network node 1, 5 (as illustrated in Fig 1A and described above) , the UE 2 being indirectly connected to the radio network node 1, 5 (as illustrated in Fig 1B and described above) , and the UE 2 not being connected to the radio network node 1, 5.
[0092] The request 20 for data for authentication and authorization of the UE 2 can comprise an identity of the radio network node requiring authentication and authorization data for one or multiple UEs. The requiring node can be the radio network node that sends the request message or a different radio network node.
[0093] In an optional transmit result step 48, the radio network node 1, 5 transmits a result 24 of the authentication and authorization to the core network 3. The core network 3 receives the result in a receive result step 148.
[0094] In an optional provide AA data to target node step 50, the radio network node 1, 5 provides the data for authentication and authorization for the UE 2 to a target radio network node of an expected change of radio network node of the UE 2.
[0095] In one embodiment, a radio network node that stores data for authentication and authorization of the UE 2 forwards the data to a target radio network node via inter radio network node interface. This may occur when the radio network node has learned that the UE 2 will be served by the target radio network node soon (e.g. due to the UE’s mobility, or replacement / relocation of the UE 2) . In one embodiment, the UE 2 moves from the coverage area of a currently serving radio network node, to a coverage area of a target radio network node.
[0096] When the UE 2 sends the uplink data to the target radio network node, the target radio network node fetches the data for authentication and authorization for the UE 2 from the previous serving / camped radio network node. In order to determine which radio network node served the UE 2, the target radio network node may send a request message querying the UE’s information to neighbouring radio network nodes. The request message may be sent via inter-radio network node interface in a unicast or broadcast manner. The request message comprises at least the UE identifier. The last serving radio network node replies to the target radio network node indicating that the last serving radio network node has stored the data of authentication and authorization for the UE 2. Thereafter, the target radio network node can fetch the data from the last serving radio network node.
[0097] Using embodiments presented herein, transmission latency for UEs can be reduced, since the UE 2 is authenticated and authorized using communication between the UE 2 and the radio network node 1, 5, instead of the UE needing to interactively communicate with the core network. By allowing the radio network node to perform authentication and authorization procedure for the UE 2. In this way, workload and energy consumption is reduced for the UE 2, which is greatly beneficial for IoT devices in general, and ambient IoT devices in particular.
[0098] Fig 3 is a schematic diagram illustrating components of the radio network node 1, 5 of Figs 1A-B. Processing circuitry 60 is provided using any combination of one or more of a suitable central processing unit (CPU) , graphics processing unit (GPU) , multiprocessor, neural processing unit (NPU) , microcontroller, digital signal processor (DSP) , etc. capable of executing software instructions 67 stored in memory circuitry 64, which can thus be a computer program product. The processing circuitry 60 could alternatively be implemented using an application specific integrated circuit (ASIC) , field programmable gate array (FPGA) , etc. The processing circuitry 60 can be configured to execute embodiments of method for the radio network node 1, 5 described with reference to Figs 2A and 2B above.
[0099] The memory circuitry 64 can be any combination of random-access memory (RAM) and / or read-only memory (ROM) . The memory circuitry 64 also comprises non-transitory persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid-state memory or even remotely mounted memory.
[0100] A data memory 66 is also provided for reading and / or storing data during execution of software instructions in the processing circuitry 60. The data memory 66 can be any combination of RAM and / or ROM.
[0101] An I / O interface 62 is provided for communicating with external and / or internal entities using wired communication, e.g. based on Ethernet, and / or wireless communication, e.g. Wi-Fi, Bluetooth, Bluetooth Low Energy, and / or a cellular network, complying with any one or a combination of sixth generation (6G) mobile networks, next generation mobile networks (fifth generation, 5G) , LTE (Long Term Evolution) , UMTS (Universal Mobile Telecommunications System) utilising W-CDMA (Wideband Code Division Multiplex) , or any other current or future wireless network, as long as the principles described hereinafter are applicable.
[0102] Other components of the radio network node 1, 5 are omitted in order not to obscure the concepts presented herein.
[0103] Fig 4 is a schematic diagram showing functional modules of the radio network nodes 1, 5 of Figs 1A-B according to one embodiment. The modules are implemented using software instructions such as a computer program executing in the radio network node 1, 5. Alternatively or additionally, the modules are implemented using hardware, such as any one or more of an ASIC (Application Specific Integrated Circuit) , an FPGA (Field Programmable Gate Array) , or discrete logical circuits. The modules correspond to the steps in the methods illustrated in Figs 2A and 2B.
[0104] An AA data need determiner 70 corresponds to step 40. An AA data requester 72 corresponds to step 42. An AA data receiver 74 corresponds to step 44. An AA performer 76 corresponds to step 46. A result transmitter 78 corresponds to step 48. An AA data provider 80 corresponds to step 50.
[0105] Fig 5 shows one example of a computer program product 90 comprising computer readable means. On this computer readable means, a computer program 91 can be stored in a non-transitory memory. The computer program can cause processing circuitry to execute a method according to embodiments described herein. In this example, the computer program product 90 is in the form of a removable solid-state memory, e.g. a Universal Serial Bus (USB) drive. As explained above, the computer program product could also be embodied in a memory of a device, such as the computer program product 64 of Fig 3. While the computer program 91 is here schematically shown as a section of the removable solid-state memory, the computer program can be stored in any way which is suitable for the computer program product, such as another type of removable solid-state memory, or an optical disc, such as a CD (compact disc) , a DVD (digital versatile disc) or a Blu-Ray disc.
[0106] The aspects of the present disclosure have mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the invention, as defined by the appended patent claims. Thus, while various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects and embodiments disclosed herein are for purposes of illustration and are not intended to be limiting, with the true scope being indicated by the following claims.
Claims
1.A method for authenticating and authorizing a user equipment, UE, (2) the method being performed by a radio network node (1, 5) of a cellular network (9) , the method comprising:receiving (44) data (22) for authentication and authorization of the UE (2) from a core network (3) ; andperforming (46) an authentication and authorization check with the UE (2) based on the data (22) for authentication and authorization.2.The method according to claim 1, further comprising, prior to the receiving (44) data (22) for authentication and authorization:determining (40) that data for authentication and authorization of the UE (2) is to be obtained; andtransmitting (42) a request (20) for data for authentication and authorization of the UE (2) to the core network (3) , wherein the request (20) comprises an identifier of the UE (2) .3.The method according to claim 2, wherein the request (20) for data for authentication and authorization of the UE (2) comprises an energy category of the UE (2) , wherein the energy category indicates an energy capability of the UE (2) .4.The method according to claim 2 or 3, wherein the request (20) for data for authentication and authorization of the UE (2) comprises a connection category of the UE (2) , wherein the connection category is one of: the UE being directly connected to the radio network node (1, 5) , the UE being indirectly connected to the radio network node (1, 5) , and the UE not being connected to the radio network node (1, 5) .5.The method according to any one of claims 2 to 4, wherein the determining (40) that data for authentication and authorization of the UE (2) is to be obtained comprises determining that the UE (2) is located within a coverage area of the radio network node (1, 5) .6.The method according to any one of claims 2 to 5, wherein the determining (40) that data for authentication and authorization of the UE (2) is to be obtained comprises determining that there is downlink data for the UE (2) .7.The method according to any one of claims 2 to 6, wherein the determining (40) that data for authentication and authorization of the UE (2) is to be obtained comprises communicating with the UE (2) .8.The method according to any one of the preceding claims, further comprising:transmitting (48) a result (24) of the authentication and authorization to the core network (3)9.The method according to any one of the preceding claims, wherein the data (22) for authentication and authorization comprises data for authentication comprising at least one of: an identifier of the UE (2) , a digital key associated with the UE (2) , a digital token associated with the UE (2) and a digital signature applied by the core network (3) .10.The method according to any one of the preceding claims, wherein the data (22) for authentication and authorization comprises data for authorization comprising at least one of: an indication that the UE (2) is authorized to operate as a UE on the cellular network (9) , an indication whether the UE (2) allows authentication and authorization by the radio network node (1, 5) , and an indication what services, traffic types or applications that the UE (2) is allowed to access.11.The method according to any one of the preceding claims, further comprising:providing (50) the data for authentication and authorization for the UE to a target radio network node of an expected change of radio network node of the UE.12.A radio network node (1, 5) for authenticating and authorizing a user equipment, UE, (2) the radio network node (1, 5) being configured to form part of a cellular network (9) , the radio network node (1, 5) comprising:processing circuitry (60) ; andmemory circuitry (64) storing instructions (67) that, when executed by the processing circuitry, cause the radio network node (1, 5) to:receive data (22) for authentication and authorization of the UE (2) from a core network (3) ; andperform an authentication and authorization check with the UE (2) based on the data (22) for authentication and authorization.13.The radio network node (1, 5) according to claim 12, further comprising instructions (67) that, when executed by the processing circuitry prior to the instructions to receive data (22) for authentication and authorization, cause the radio network node (1, 5) to:determine that data for authentication and authorization of the UE (2) is to be obtained; andtransmit a request (20) for data for authentication and authorization of the UE (2) to the core network (3) , wherein the request (20) comprises an identifier of the UE (2) .14.The radio network node (1, 5) according to claim 13, wherein the request (20) for data for authentication and authorization of the UE (2) comprises an energy category of the UE (2) , wherein the energy category indicates an energy capability of the UE (2) .15.The radio network node (1, 5) according to claim 13 or 14, wherein the request (20) for data for authentication and authorization of the UE (2) comprises a connection category of the UE (2) , wherein the connection category is one of: the UE being directly connected to the radio network node (1, 5) , the UE being indirectly connected to the radio network node (1, 5) , and the UE not being connected to the radio network node (1, 5) .16.The radio network node (1, 5) according to any one of claims 13 to 15, wherein the instructions to determine that data for authentication and authorization of the UE (2) is to be obtained comprise instructions (67) that, when executed by the processing circuitry, cause the radio network node (1, 5) to determine that the UE (2) is located within a coverage area of the radio network node (1, 5) .17.The radio network node (1, 5) according to any one of claims 13 to 16, wherein the instructions to determine that data for authentication and authorization of the UE (2) is to be obtained comprise instructions (67) that, when executed by the processing circuitry, cause the radio network node (1, 5) to determine that there is downlink data for the UE (2) .18.The radio network node (1, 5) according to any one of claims 13 to 17, wherein the instructions to determine that data for authentication and authorization of the UE (2) is to be obtained comprise instructions (67) that, when executed by the processing circuitry, cause the radio network node (1, 5) to communicate with the UE (2) .19.The radio network node (1, 5) according to any one of claims 12 to 18, further comprising instructions (67) that, when executed by the processing circuitry, cause the radio network node (1, 5) to:transmit a result (24) of the authentication and authorization to the core network (3)20.The radio network node (1, 5) according to any one of claims 12 to 19, wherein the data (22) for authentication and authorization comprises data for authentication comprising at least one of: an identifier of the UE (2) , a digital key associated with the UE (2) , a digital token associated with the UE (2) and a digital signature applied by the core network (3) .21.The radio network node (1, 5) according to any one of claims 12 to 20, wherein the data (22) for authentication and authorization comprises data for authorization comprising at least one of: an indication that the UE (2) is authorized to operate as a UE on the cellular network (9) , an indication whether the UE (2) allows authentication and authorization by the radio network node (1, 5) , and an indication what services, traffic types or applications that the UE (2) is allowed to access.22.The radio network node (1, 5) according to any one of claims 12 to 21, further comprising instructions (67) that, when executed by the processing circuitry, cause the radio network node (1, 5) to:provide the data for authentication and authorization for the UE to a target radio network node of an expected change of radio network node of the UE.23.A computer program (67, 91) for authenticating and authorizing a user equipment, the computer program comprising computer program code which, when executed on a radio network node (1, 5) forming part of a cellular network (9) causes the radio network node (1, 5) to:receive data (22) for authentication and authorization of the UE (2) from a core network (3) ; andperform an authentication and authorization check with the UE (2) based on the data (22) for authentication and authorization.24.A computer program product (64, 90) comprising a computer program according to claim 23 and a computer readable means comprising non-transitory memory in which the computer program is stored.
Citation Information
Patent Citations
Method of Local Authentication / Authoization / AccountingFunction in All IP Net
KR1020020057293A